ClaudeMods
☰
KO
● 0 명 접속 중 · 조회 0 회
후원프로젝트 제출
Reddit 게시물 · 작성자 Sea-University-7237

I approved an agent’s “oc delete —all” without reading it, so I built guardrails (and 10 other mods) with Claude Code’s new function hooks

The author nearly wiped a Kubernetes namespace after approving an agent’s `oc delete --all` without reading it, then built a suite of 11 Claude Code plugins using the new function hooks API. The main mod, guardrails, blocks destructive commands like mass kubectl/oc deletes, rm -rf, force-push, and secret reads, and tells Claude the user blocked it. Other mods cover activity monitoring, desktop notifications, context tracking, usage limits, prompt coaching, command discovery, and a mod manager. Nine of eleven never call a model, there is no telemetry, and the project is free and MIT licensed.

번역 준비 중

이 mod 소개

Reddit post by u/Sea-University-7237 describing a suite of 11 Claude Code plugins built with the new function hooks API, prompted by an incident where the author approved an agent’s oc delete --all without reading it and partially wiped a namespace. The flagship mod, guardrails, lets users toggle rules to block rm -rf, mass kubectl/oc deletes, force-push, destructive git operations, .env reads, installs, and network access, and signals to Claude that the user blocked the action so it will not work around it. Remaining mods: activity, notify, context-keeper, usage-meter, prompt-coach, command-hub, toolbox, changes, loop-breaker, a quickbar launcher, and /mods for installing and toggling them. Nine mods never call a model; prompt-coach and a context-keeper handoff note go through Claude Code. No telemetry beyond a marketplace update check. The README documents every process and file touched. Limits: guardrails inspects commands passed to tools, so it would catch oc delete --all but not a script the agent writes and later runs. Install with claude plugin marketplace add mishgoldenberg/claude-mods and claude plugin install mod-manager@claude-mods, then restart and run /mods. Requires Claude Code 2.1.286+. Repo: https://github.com/mishgoldenberg/claude-mods

설치

설치 방법은 원본 출처를 확인하세요.

원문 / README

A while ago I asked an agent (Claude Code on a self-hosted model) to "delete everything you added in the last command". It came back with oc delete --all. I hit approve without reading it, and it started wiping the namespace. I caught it about halfway. Rebuilding the rest from Confluence pages took me two days. Claude Code recently added function hooks, which are plugins that run inside it, see every tool call before it executes, and can draw their own panels. So I built the stuff I wish I'd had that day. The one that matters most is guardrails. You click rules on or off: block rm -rf, mass kubectl/oc deletes, force-push, destructive git, reading .env, installs, network, or keep Claude inside the project folder. When it blocks something it tells Claude the user blocked it and not to work around it. The rest: - activity: shows what Claude is running right now, for how long, and when it's waiting for your approval - notify: a desktop notification (Windows/macOS/Linux) when a long task finishes or an approval has been sitting there - context-keeper: what's filling your context window, plus checkpoints saved to disk so /compact and /clear don't lose the thread - usage-meter: 5h/7d limit bars with burn rate and cache hit ratio - prompt-coach: when a prompt is vague (like mine was), it suggests a sharper version and you pick which one to send. It never rewrites anything silently - command-hub: the built-in commands people miss (/rewind, /btw, /context) explained, plus a form to make your own - toolbox, changes, loop-breaker (catches Claude retrying the same failing command), a quickbar launcher, and /mods to install and toggle all of them Nine of the eleven never call a model, so they cost no tokens. The two that do (prompt-coach and the context-keeper handoff note) go through Claude Code itself. There's no telemetry, and the only other network traffic is the marketplace check when you click update in /mods. The README lists every process and file they touch. To be clear about the limits: guardrails is a seatbelt, not a sandbox. It checks the command the agent passes to a tool, so it would have caught my oc delete --all, but it won't catch a script the agent writes and then runs. How Claude helped: I built the whole thing in Claude Code (Opus). I wrote the feature list and the rules I wanted. Claude read the function hooks API types, wrote the mods, ran the plugin validator on each one, and wrote the tests (64 on the guardrail rules, running in CI). My job was testing in the real desktop app and reporting what broke. Funny part: its own guardrails kept blocking its edits during the build, and it fixed the rule instead of working around it. What I learned: - How you deny matters more than what you deny. A plain "blocked" makes the model try a reworded command. "The user blocked this, don't work around it, ask them" makes it stop and explain. - Matching raw command text is noisy. Commit messages that just mentioned rm -rf got blocked. Ignoring quoted text (unless the command runs a shell inline like bash -c or | sh) fixed most of it. - Anything that changes what gets sent to the model has to be visible. A silent prompt rewriter is worse than none. It's free and MIT licensed, no account needed. Install: claude plugin marketplace add mishgoldenberg/claude-mods claude plugin install mod-manager@claude-mods Then restart and type /mods. Needs Claude Code 2.1.286 or newer. Repo: https://github.com/mishgoldenberg/claude-mods What annoys you in Claude Code that a mod could fix? I'm picking the next ones from the comments. submitted by /u/Sea-University-7237 [link] [comments]

비슷한 프로젝트